BitMaskOS: A Capability-Native Operating System Abstraction for AI Service Meshes
Fuente:
Zenodo
Guardado en:
| Autor principal: | |
|---|---|
| Formato: | Recurso digital |
| Publicado: |
Zenodo
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
| _version_ | 1866901167970189312 |
|---|---|
| author | Sharma, Anil |
| author_facet | Sharma, Anil |
| contents | ANKR Research Papers #85. BitMaskOS (BMOS) is an operating system abstraction for AI service meshes, replacing probabilistic capability discovery with O(1) bitwise proof. Drawing on classical OS primitives — process descriptors, capability tables, syscall gates, fault isolation, and init systems — BMOS maps each to a bitmask equivalent: codex.json (process descriptor), AnkrCodex (process table), trust_mask (process capabilities), perm_mask (thread capabilities), KAVACH (kernel syscall gate), and gate valve (fault isolation without restart). The paper introduces BMOS-Authorize: a service-level authorization endpoint that checks capability intersection at call time, completing the OS analogy. KAVACH handles agent-level (thread) enforcement; BMOS-Authorize handles service-level (process) enforcement. Two layers, same primitive: bitwise AND. Validated across 236 ANKR services with declared trust_masks. v2 (2026-04-30): BMOS-Authorize shipped. Section 8.3 added with live implementation evidence: measured p50 latency 8-11us across 236-service mesh, full audit log, codex.json protocol declaration (protocol: bitmask-os-v1). Status updated Pending to Live in Section 8.1. |
| format | Recurso digital |
| id | zenodo_https___doi_org_10_5281_zenodo_19937211 |
| institution | Zenodo |
| language | |
| publishDate | 2026 |
| publisher | Zenodo |
| record_format | zenodo |
| spellingShingle | BitMaskOS: A Capability-Native Operating System Abstraction for AI Service Meshes Sharma, Anil bitmask operating system capability-native architecture AI service mesh KAVACH trust_mask perm_mask BMOS-Authorize O(1) authorization gate valve microservice security agent capability enforcement AnkrCodex zero hallucination ANKR Research Papers #85. BitMaskOS (BMOS) is an operating system abstraction for AI service meshes, replacing probabilistic capability discovery with O(1) bitwise proof. Drawing on classical OS primitives — process descriptors, capability tables, syscall gates, fault isolation, and init systems — BMOS maps each to a bitmask equivalent: codex.json (process descriptor), AnkrCodex (process table), trust_mask (process capabilities), perm_mask (thread capabilities), KAVACH (kernel syscall gate), and gate valve (fault isolation without restart). The paper introduces BMOS-Authorize: a service-level authorization endpoint that checks capability intersection at call time, completing the OS analogy. KAVACH handles agent-level (thread) enforcement; BMOS-Authorize handles service-level (process) enforcement. Two layers, same primitive: bitwise AND. Validated across 236 ANKR services with declared trust_masks. v2 (2026-04-30): BMOS-Authorize shipped. Section 8.3 added with live implementation evidence: measured p50 latency 8-11us across 236-service mesh, full audit log, codex.json protocol declaration (protocol: bitmask-os-v1). Status updated Pending to Live in Section 8.1. |
| title | BitMaskOS: A Capability-Native Operating System Abstraction for AI Service Meshes |
| topic | bitmask operating system capability-native architecture AI service mesh KAVACH trust_mask perm_mask BMOS-Authorize O(1) authorization gate valve microservice security agent capability enforcement AnkrCodex zero hallucination |
| url | https://doi.org/10.5281/zenodo.19937211 |